Skip to content

Conversation

@EmielBruijntjes
Copy link

Hello,

When running 'freight-cache', a temporary working directory is created in $VARCACHE. And because $VARCACHE is also normally exposed via a webserver, the temporary files in this directory are also accessible from the outside. I'm not sure if this is a vulnerability, maybe it it not even an issue, but I find it not so elegant. In this pull request I added a config-option $TEMPDIR that can be set to use a different temporary directory instead.

Maybe it helps someone.

Emiel Bruijntjes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant